[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3dy1tqrv9wcxb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":31,"seoTitle":32,"seoDescription":33,"logoUrl":34,"isVerified":35,"isSensitive":35,"isSpamList":35,"isMalware":35,"company":36},"6a457a04bcfb3dce02ce5f47","ccaa","CCAA Alleged Data Exposure","ccaa.com.br","2021-08-01T00:00:00.000Z","2026-07-01T20:35:16.239Z",null,"2026-09-17T16:27:41.515Z","2026-07-19T00:04:20.268Z","Third party breach","",[],975533,"known","email_identifiers","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30],"Email addresses","Passwords","\u003Cp>The CCAA data breach is a record dated August 2021 associated with the Brazil-based language education and learning platform ccaa.com.br. The record covers approximately 975,533 users, and the supported data classes are email addresses and passwords. It has been reported that password data was stored in a WordPress-based hash format. While this is better than plain text passwords, it is not sufficient assurance on its own; weak or reused passwords can still be tried by attackers. Since official entity verification is limited, the record is not marked as verified. Due to the educational context, the email and password risk is particularly significant for student and course accounts.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>The CCAA record contains email addresses and passwords. The password being in hashed form means that an attacker may not be able to read it directly; however, the risk persists for weak passwords and reused patterns. On educational platforms, users may use the same email address for courses, schools, payments, student portals, and personal accounts. Therefore, attackers can use the email list for phishing, fake course notifications, or password-guessing attacks. Under this record, name, phone number, payment information, student grade, or ID verification have not been included because they are not verified.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The CCAA record appears in open violation records with approximately 975,000 user rows, but it is not in a verified status because there is no detailed official statement. The supported data classes are email and password. The information that passwords are stored in a WordPress-style hash format should not be described as a plain text leak; however, it does not make password reuse safe. This explanation does not make definitive statements such as student profile, grades, course enrollment, or payment data being leaked. The risk is that the educational account email and password hash circulate together.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>CCAA students, former trainees, parents, instructors, and people who use the same email address for different educational services are at risk. If the password used for the CCAA account is repeated in email, school portal, social media, or payment services, attackers may try to access these accounts. Since education-themed messages appear trustworthy, fake emails such as exam, course renewal, payment reminder, or certificate notifications can be more convincing. Young users and family accounts should be especially careful against such messages.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users with a CCAA match should change the password they used during the relevant period and clean up all accounts where the same password is repeated. Two-step verification should be enabled on the email account, and links related to training or courses should not be used outside of the official channel. If a payment request comes through a student or parent account, it should be verified directly through the institution's known communication channel. Even if the password appears in hash form, it should not be forgotten that short or predictable passwords can be quickly cracked.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In educational accounts, personal email, school email, and payment accounts should be kept separate. A unique password should be used for each educational platform, and a password manager should be preferred. Parents should check that the same password is not repeated in their child or young user's accounts. For emails from courses and certificate services, login should be done through the known domain name instead of links. Unused old educational accounts should be closed or at least updated with a strong and unique password.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If a CCAA match is seen in the LeakData check, the user should consider this as a risk to the training account email and password hash. The record is not in a verified status; however, action should be taken due to approximately 975 thousand records and password fields. The first step is to change all accounts using the same password, the second step is to strengthen the email account with two-factor authentication, and the third step is to be cautious against fake messages themed around training or payment. A match does not mean that payment or grade data has been leaked. This distinction ensures that the user both sees the correct risk and is not misled by unnecessary data claims.\u003C\u002Fp>","CCAA Alleged Data Exposure (975.5 Thousand Email Identifiers)","CCAA Alleged Data Exposure. 975.5 Thousand email identifiers are reported. Reported data: Email addresses, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fccaa.png",false,{"name":37,"sector":38,"country":39,"website":9,"websiteArchiveUrl":16,"websiteStatus":16,"websiteCheckedAt":12},"CCAA","Education \u002F Language Learning","Brazil"]